CVE-2021-23336 | cpython up to 3.6.12/3.7.9/3.8.7/3.9.1 urllib.parse.parse_qsl/urllib.parse.parse_qs request smuggling (SNYK-UPSTREAM-PYTHONCPYTHON-1074933 / Nessus ID 211197)
A vulnerability, which was classified as critical, was found in cpython up to 3.6.12/3.7.9/3.8.7/3.9.1. Affected is the function urllib.parse.parse_qsl/urllib.parse.parse_qs. The manipulation leads to http request smuggling.
This vulnerability is traded as CVE-2021-23336. It is possible to launch the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.